Appending a Security-Requirements Section to a Vibe-Coding Prompt Cut Confirmed Findings From 51 to 24 Across Six Web Apps
Vibe Coding and Web Application Security (arXiv 2608.20963, Aug 21) generated six functionally distinct web applications twice with the same agentic coding assistant and model version, the twin prompts identical except for an appended security-requirements section. Static, dependency, dynamic and manual analysis of all twelve programs confirmed 75 of 85 candidate findings; the security-aware variant produced fewer confirmed findings in every single application (24 versus 51) and contained no Critical or High issues. The most severe finding in the corpus was detected only by manual testing, and the authors flag the small single-generation corpus and report descriptive observations rather than statistical effects.
↳ Follow the thread